Your books are walled off. By design.

How we protect your data today, in plain language, and what we have not done yet.

free plan forever · 14-day trial · no card

Tenant isolation on the server

Which company’s data you see is decided on the server from your signed-in account, never from the URL or the browser.

Roles and permissions

14 role templates and 51 permissions; access is granted per company.

Full audit trail

Sign-ins and changes are recorded with who, when, from where, and values before and after. Secrets are never written to it.

Hardened sign-in

Passwords stored with modern one-way hashing, sign-in throttling per account and per network, sessions renewed at sign-in and expired when idle.

Protected forms

Every form is protected against cross-site request forgery; output is escaped against script injection.

Records that do not change

Issued documents are locked; corrections are made with new documents so the history is complete.

Encrypted secrets

Credentials such as mail server passwords are encrypted with AES-256-GCM.

Encrypted in transit

The service runs over HTTPS.

Safe updates

Updates are verified by checksum, backed up first and rolled back automatically if anything fails.

Not yet: One does not hold SOC 2 or ISO 27001 certification, and two-factor authentication is not available yet. We will list certifications here only once they are issued. To report a security issue, use the contact form.

Start with one place for the whole business.

Free plan forever. 14-day trial on paid plans, no card. We set you up within one working day.